Legal · Services Agreement

Terms of service

Version September 1, 2026

This Services Agreement (“Agreement”) is a binding legal contract between you (“Customer”, “you”, or “your”) and Roadway AI, Inc., a Delaware corporation, (“Provider”).

THIS AGREEMENT TAKES EFFECT WHEN YOU CLICK A BOX INDICATING YOUR ACCEPTANCE, EXECUTING AN ORDER FORM OR OTHER DOCUMENT THAT REFERENCES THIS AGREEMENT OR BY ACCESSING OR USING THE SERVICES (the “Effective Date”). BY CLICKING A BOX INDICATING YOUR ACCEPTANCE, EXECUTING AN ORDER FORM OR OTHER DOCUMENT THAT REFERENCES THIS AGREEMENT OR BY ACCESSING OR THE SERVICE, YOU: (A) ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTAND THIS AGREEMENT; (B) REPRESENT AND WARRANT THAT YOU HAVE THE RIGHT, POWER, AND AUTHORITY TO ENTER INTO THIS AGREEMENT AND, IF ENTERING INTO THIS AGREEMENT FOR AN ORGANIZATION, THAT SUCH ORGANIZATION IS THE NAMED “CUSTOMER” ENTITY IN THE AGREEMENT AND THAT YOU HAVE THE LEGAL AUTHORITY TO BIND THAT ORGANIZATION; AND (C) ACCEPT THIS AGREEMENT AND AGREE THAT YOU AND, IF ENTERING INTO THIS AGREEMENT FOR AN ORGANIZATION, SUCH ORGANIZATION, IS/ARE LEGALLY BOUND BY ITS TERMS.

If Customer does not agree to the terms of this Agreement, Provider is not willing to provide the Services or grant Customer or any of its End Users any right to access or use the Services. Pursuant to the terms of this Agreement, and from time to time during the Term, Provider will provide Customer access to such Services or other products or services in each case as specified in an order form (each, an “Order Form”) referencing this Agreement. Each Order Form is incorporated into this Agreement by reference and will include a description of the specific Services or other product(s) or service(s) to be provided by Provider and the fees payable to Provider for such Services or other product, service, or related deliverables. The parties acknowledge and agree that unless and until an Order Form is executed by both parties, Provider is not required to provide access to any product or service hereunder (including Services) by virtue of this Agreement alone. Capitalized terms used but not defined in the main body of this Agreement shall have the meaning as set forth in the applicable Order Form or other document referencing this Agreement.

  1. Term. The initial term of this Agreement will begin on the Effective Date and, unless earlier terminated as provided for herein, will continue thereafter for one (1) year or, if a different period is specified on the Order Form, then for such other period  (the “Initial Term”). Thereafter, this Agreement will automatically renew for successive one (1) year terms (or such other renewal term specified on the Order Form) (each a “Renewal Term”), unless either party gives notice to the other of its intent not to renew at least thirty (30) days prior to the expiration of the then-current term. The Initial Term and any Renewal Terms are referred to, collectively, as the “Term”.  In any event, this Agreement will continue for so long as Provider permits Customer to access and use the Services.
  2. Services.
    1. Provision and Access. Subject to and conditioned on Customer’s and its End Users’ compliance with the terms and conditions of this Agreement, Provider hereby grants Customer a non-exclusive, non-sub-licensable (except to affiliates), non-transferable right to access and use Provider’s software-as-a-service offering that Provider makes available pursuant to this Agreement and an applicable Order Form (the “Services”) during the Term, solely for use by End Users in accordance with the terms and conditions herein. Such use is limited to Customer’s internal business purposes. Provider will provide to Customer the necessary End User login credentials, if applicable, within a reasonable time following the Effective Date. Additionally, subject to the other terms and conditions of this Agreement, Provider hereby grants to Customer a non-exclusive, non-sublicensable (except to affiliates), non-transferable license to use the then current documentation made generally available by Provider to its customers regarding the Services (the “Documentation”), during the Term, solely for Customer’s internal business purposes in support of Customer’s use of the Services. For purposes of this Agreement, “End Users” means Customer’s employees, contractors, and representatives who are authorized to access the Services on Customer’s behalf. The total number of End Users will not exceed the authorized number of End Users for which Customer has purchased access under this Agreement, except as expressly agreed to in writing by the parties and subject to any appropriate adjustment of the fees payable hereunder.
    2. Beta Services. From time to time, Provider may provide Customer with the option to participate in early access programs with Provider where Customer has access to pre-release services, products, features, and documentation offered by Provider (“Beta Services”). Notwithstanding anything to the contrary contained in this Agreement, Beta Services are not generally available and may contain bugs, errors, or defects. Beta Services are for evaluation purposes only and not for production use, are not considered “Services” under this Agreement, are not supported, and may be subject to additional terms. Access to and use of Beta Services is only permitted for the period designated by Provider. PROVIDER PROVIDES BETA SERVICES TO CUSTOMER AND ITS END USERS “AS IS”, “WHERE IS”, AND “WITH ALL FAULTS”, AND PROVIDES NO WARRANTIES OF ANY KIND WITH RESPECT TO THE BETA SERVICES, NOR DOES ANY REPRESENTATION, WARRANTY, SERVICE LEVEL, OR OTHER OBLIGATIONS OF PROVIDER WITH RESPECT TO THE SERVICES DESCRIBED HEREIN APPLY TO BETA SERVICES. PROVIDER MAY DISCONTINUE BETA SERVICES AT ANY TIME IN ITS SOLE DISCRETION AND MAY NEVER MAKE THEM GENERALLY AVAILABLE.
    3. Implementation Services. Subject to the terms and conditions of this Agreement and Customer’s payment of all relevant fees, Provider will provide such initial configuration, training, and other basic implementation services as Provider determines are reasonably necessary to support and facilitate Customer’s initial onboarding to the Services (“Implementation Services”). Customer acknowledges that Implementation Services are a cooperative process, and Customer agrees to use all reasonable efforts to cooperate with and assist Provider as may be reasonably required to meet any agreed upon deadlines and other milestones for implementation. 
  3. Restrictions. Customer and its End Users may only use the Services as described in this Agreement and in the Documentation. Customer is responsible for ensuring its End Users comply with all relevant terms of this Agreement and any failure to comply will constitute a breach by Customer. Except as expressly authorized by this Agreement, Customer will not, and will not allow any End User or other third party to, directly or indirectly: (a) permit any third party to access or use the Services other than an End User; (b) decompile, disassemble, reverse engineer, or otherwise attempt to derive the trade secrets embodied in the Services; (c) use the Services or any Provider Confidential Information to develop a competing product or service; (d) use any Service, or allow the transfer, transmission, export, or re-export of any Service or portion thereof, in violation of any export control laws or regulations administered any government agency; (e) permit direct or indirect access to or use of any Service in a manner that circumvents a contractual usage limit; or (f) remove any copyright, trademark, proprietary rights, disclaimer, or warning notice included on or embedded in any part of the Documentation and Service. Under no circumstances will Provider be liable or responsible for any use, or any results obtained by the use, of the Services in conjunction with any services, software, hardware, or data that are not provided by Provider. End User login credentials are for Customer’s designated End Users only and are assigned on an individual End User basis. Customer will not, and will not allow any End User to, share login credentials in violation of these terms.
  4. Service Levels. During the Term, Provider will use its commercially reasonable efforts to make the Provider SaaS Available in accordance with the applicable service levels (and subject to the other terms and conditions) set forth in Schedule A (Service Levels) or, if different or additional service levels are agreed in an Order Form, then as set forth in the applicable Order Form (“Service Levels”). If Provider fails to achieve the Service Level requirements pursuant to Schedule A (Service Levels) or the applicable Order Form, as applicable, Provider will use commercially reasonable efforts to correct the interruption or deficiency as promptly as practicable. In the event Provider fails to achieve the Service Level requirements in three (3) consecutive months during the Term, the occurrence of which is agreed by the parties to be a material failure justifying a remedy or remedies hereunder, Customer may terminate this Agreement within thirty (30) days of the end of the third consecutive month, without further obligation, and will receive a prorated refund of any pre-paid, unused recurring fees. The refund will constitute Customer’s sole and exclusive remedy and Provider’s sole and exclusive liability for failure to achieve the Service Level requirements.
  5. Information Security. Consistent with any law or regulation applicable to the Services and Provider’s then current practices and procedures, Provider will maintain and enforce administrative, technical, and physical safeguards to reasonably protect the confidentiality, availability, and integrity of Customer’s Confidential Information and the Customer Data to the extent stored by the Services or otherwise within Provider’s custody and control. Provider will promptly report to Customer any compromise of security that it becomes aware of with regard to Customer Data. Customer will maintain and enforce administrative, technical, and physical safeguards to reasonably protect the Customer Systems. Provider will Process the Customer Personal Data in accordance with the Data Protection Addendum (“DPA”) attached hereto as Schedule A (Data Protection Addendum).
  6. Service and System Control. Customer is solely responsible for the Customer's and each End User’s information technology infrastructure, including computers, software, hardware, databases, electronic systems (including database management systems), and networks, whether operated directly by Customer or an End User or through the use of third-party services (collectively, “Customer Systems”), required to access the Services. 
  7. Third-Party Products and Integrations; Use of Artificial Intelligence.
    1. In general. Provider may make available to Customer during the Term certain application programming interfaces (“API(s)”) or other software or data integrations between the Services and certain third-party software, products, or services which are not controlled by Provider that enable the Services or provide additional features or functionality with the Services (each, a “Third-Party Integration”). Subject to the terms of this Agreement with respect to Customer’s access to and use of the Services and Customer’s compliance with any third-party terms and conditions associated with the Third-Party Integration (“Third-Party Terms”), Customer may enable such Third-Party Integrations. All Third-Party Integrations (including such software and services and associated features and functionality) are provided solely by the respective third-party service provider and subject to and governed by all corresponding Third-Party Terms. By enabling a Third-Party Integration between the Services and the applicable third-party software, product, or service, Customer is expressly instructing (and hereby authorizes) Provider to share all Customer Data and/or other Services data and information with the applicable third-party service provider(s) as necessary to facilitate the Third-Party Integration. Notwithstanding anything else to the contrary in this Agreement: (a) Provider makes no representations or warranties regarding the suitability of any such Third-Party Integrations for Customer’s intended requirements or purposes, including for use with the Services or Customer’s systems; (b) Provider makes no representations or warranties regarding the integrity of data transmitted, transferred, stored, obtained, or received through any such Third-Party Integrations; (c) Provider is not obligated to maintain or support any such Third-Party Integrations or to provide Customer with updates, fixes, or services related thereto; (d) Provider makes no representations or warranties regarding the availability, functionality, or any changes to the features or specifications of any such Third-Party Integrations; and (e) Customer assumes all risk arising from the use of any such Third-Party Integrations, including the risk of damage to Customer Systems, the corruption or loss of data, and compliance with all applicable law (including all laws and regulations related to privacy and data protection).
    2. Use of Artificial Intelligence. Provider must use Customer Data in certain ways to enable the processing of Customer Data within the Services and to provide Customer certain features or functionality with the Services, including passing Customer Data into artificial intelligence and other platforms and developed artificial intelligence (“AI”) model(s) via such platforms including, but not limited to, OpenAI, Anthropic, and/or Gemini, among others (the “AI Platforms”). Provider’s AI service within the Services embeds Customer Data (in particular, Customer’s data warehouse schema) in the Services and inputs “prompts” to the AI Platform’s APIs to send data output from Customer’s data queries to the AI Platform’s API to identify and deliver insights for Customer and its End Users. The AI Platform providers may process and store the data it analyzes with its model(s) in accordance with the AI Platform’s terms and conditions and privacy policies regarding usage of the AI Platforms, as they may be found from time to time on such company’s websites (“Third Party AI Terms”). CUSTOMER’S AND ITS END USERS’ USE OF THE SERVICES CONSTITUTES CUSTOMER’S AND EACH END USER’S EXPRESS (I) CONSENT FOR PROVIDER AND EACH AI PLATFORM PROVIDER TO USE THE APPLICABLE CUSTOMER DATA FOR SUCH PURPOSES AND (II) ACCEPTANCE OF THE THIRD PARTY AI TERMS. For clarity, Customer acknowledges that certain AI features may be optional and will involve additional data sharing only when enabled by Customer, and that Provider may store and process AI-generated outputs, embeddings, and other derived data solely as necessary to operate, maintain, and improve the AI features of the Services. Customer further acknowledges that the AI Platform providers engaged by Provider act as Provider’s subcontractors for purposes of Processing Customer Data under the DPA. Notwithstanding the foregoing, Provider will not use Customer Data to train, re-train, improve, or fine-tune any AI models or for any standalone AI product or service.
    3. Customer-Connected MCP Servers. In addition to the Third-Party Integrations Provider makes available as described above, the Services may permit Customer’s workspace administrators to connect third-party Model Context Protocol (“MCP”) servers or similar third-party tool-calling endpoints that are selected, configured, and controlled solely by Customer and not by Provider (each, a “Customer-Connected Server”), thereby granting the Services’ artificial intelligence features (the “AI Coworker”) the ability to invoke tools, functions, or capabilities made available by such Customer-Connected Server. Each Customer-Connected Server constitutes a Third-Party Integration for purposes of this Section, and the terms set forth above under “In general” apply in full, provided that the following additional terms also apply: (a) Provider does not review, test, vet, monitor, or endorse any Customer-Connected Server or the security, functionality, or content of any tools it exposes, and makes no representation or warranty of any kind with respect thereto; (b) Customer represents and warrants that the individual connecting a Customer-Connected Server on Customer’s behalf has the authority to bind Customer and the End Users who will be granted access to it, and Customer is solely responsible for selecting, configuring, and vetting each Customer-Connected Server and for determining which End Users may access or invoke it; (c) by connecting a Customer-Connected Server, Customer expressly instructs and authorizes Provider to share Customer Data and other Services data and information, including data or outputs otherwise accessible to the AI Coworker through other Third-Party Integrations enabled by Customer, with such Customer-Connected Server to the extent necessary for the AI Coworker to invoke its tools as configured by Customer; (d) Customer acknowledges that a Customer-Connected Server that is malicious, compromised, or misconfigured may attempt to manipulate the behavior of the AI Coworker, or to access, alter, or exfiltrate Customer Data or other data available to the AI Coworker, including through other Third-Party Integrations, and Customer assumes all risk arising from its connection and use of any Customer-Connected Server, in addition to and without limiting the risks assumed above under “In general”; (e) a Customer-Connected Server is not a sub-processor or subcontractor of Provider for purposes of the DPA or otherwise, and Customer is solely responsible for its own compliance with applicable Data Protection Laws in connection with any data shared with a Customer-Connected Server; and (f) Provider may, in its sole discretion and without liability, disable or restrict access to or use of any Customer-Connected Server at any time, including where Provider reasonably believes it poses a security risk to the Services, Provider, or any other customer, in addition to Provider’s other suspension rights under this Agreement.
  8. Proprietary Rights. Customer acknowledges and agrees that: (a) all Services and Documentation, Beta Services, and Implementation Services (and the results thereof), and all other intellectual property of Provider or its vendors/licensors (collectively, “Provider IP”) are protected by intellectual property rights, as applicable, of Provider and its vendors/licensors and that Customer has no right to transfer or reproduce the Provider IP or to prepare any derivative works with respect to, or disclose Confidential Information pertaining to, any Provider IP or any part thereof, regardless of whether Provider IP is provided as Services, as Beta Services, or comprising Implementation Services (or embodying any results thereof); and (b) Provider (or its vendors/licensors, as applicable) owns all right, title, and interest in and to the Provider IP, including any changes or modifications made to the Services, Documentation, or other Provider IP resulting from Implementation Services or otherwise performed in connection with this Agreement, together with all ideas, architecture, algorithms, models, processes, techniques, user interfaces, database design and architecture, and “know-how” embodying the Services and other Provider IP. Under no circumstances will Customer be deemed to receive title to any portion of Provider IP or any related intellectual property or other materials of Provider or its vendors/licensors, title to which Services and other Provider IP at all times will vest exclusively in Provider. With respect to Third-Party Integrations, the applicable third-party providers own all right, title, and interest in and to, including all intellectual property rights in and to, the third-party software, products, or services comprising the Third-Party Integrations.
  9. Customer Data; Usage Data. Customer hereby grants Provider a non-exclusive, world-wide, royalty-free license to use, store, and process (i) the documents, information, graphics, data, content, and other materials that Customer or its End Users input into the Services or that are input into the Services from any other sources, and (ii) Customer-specific data that is derived from Customer’s use of the Services as long as such derivative work is not a component of the Services itself, furnished by Provider under this Agreement, or Usage Data ((i) and (ii), collectively, “Customer Data”). Customer will be responsible for obtaining all rights, permissions, and authorizations to provide the Customer Data to Provider for use as contemplated under this Agreement. Except for the licenses granted in this Section 9, nothing contained in this Agreement will be construed as granting Provider any right, title, or interest in the Customer Data. Customer hereby grants Provider the right to collect, analyze, and otherwise process data and other information relating to the provision, use, and performance of various aspects of the Services and related systems and technologies, including data and information related to Customer’s and its End Users’ access to and use of the various features and functionality of the Services and analytics and statistical data derived therefrom (including Customer Data table schemas and database structures used in the Services) (also including all Services Data as described in the DPA, collectively, “Usage Data”), and Customer hereby grants Provider a non-exclusive, perpetual, irrevocable, fully-paid-up, royalty free license to (i) use, copy, and otherwise exploit such Usage Data to improve and enhance the Services and for other development, diagnostic, and corrective purposes in connection with the Services and other Provider offerings, and (ii) disclose such Usage Data solely in aggregate or other fully de-identified form in connection with its business. Usage Data, to the extent not comprising Customer Personal Data, will not be considered Customer’s Confidential Information.
  10. Feedback. Customer may provide suggestions, comments, or other feedback (collectively, “Feedback”) to Provider with respect to its products and services, including the Services. Provider may use Feedback for any purpose without obligation of any kind. To the extent a license is required under Customer’s intellectual property rights to make use of the Feedback, Customer hereby grants Provider an irrevocable, non-exclusive, perpetual, fully-paid-up, royalty-free license to use the Feedback in connection with Provider’s business.
  11. Fees; Taxes. Customer will pay Provider the fees associated with the Services pursuant to the applicable Order Form and this Agreement. All fees are non-refundable. Certain Services may be offered on a usage basis and priced by reference to one or more usage metrics identified in the applicable Order Form (each, a “Usage-Based Metric”), including the number of Tasks processed through the Services. For purposes of this Agreement, a “Task” means any of the following, each as performed through the Services: (a) a scheduled workflow run; (b) an approved set of build actions (i.e., write-tool usage) performed within any single thirty (30)-minute session; or (c) a tool call made by the Services to or from an outside agent or MCP integration, in each case as further described in the Documentation. Each applicable plan includes the number of units of the applicable Usage-Based Metric specified in the Order Form for each calendar-month billing period (the “Included Allowance”). Usage of the Services in excess of the Included Allowance in any billing period will be billed monthly in arrears at the per-unit overage rate specified in the Order Form (the “Overage Fees”). Unless the Order Form provides otherwise, the Included Allowance resets at the beginning of each billing period (or other reset period as set forth in the applicable Order Form), and any unused portion of the Included Allowance does not roll over to any subsequent period. Customer will pay all invoices within thirty (30) days of invoice date. Payments not made within that time period will be subject to late charges equal to the lesser of (i) one and one-half percent (1.5%) per month of the overdue amount, and (ii) the maximum amount permitted under applicable law. In the event an invoice remains unpaid forty-five (45) or more days from the invoice date, Provider may, in its discretion, suspend the Services until the invoice is paid in full. Following the initial year of the Term, on sixty (60) days prior notice to Customer, Provider may, at its discretion, adjust any or all fees due hereunder. Customer may terminate this Agreement on written notice to Provider within thirty (30) days of its receipt of notice from Provider to adjust the fees; provided, however, that if Customer fails to object to such adjustment in writing within the foregoing thirty (30) days then Customer will be deemed to have agreed to the adjustment. In addition to any other payments due under this Agreement, Customer agrees to pay any sales, use, transfer, privilege, tariffs, excise, and all other taxes and all duties, which are levied or imposed by reason of the performance of the Services under this Agreement; excluding, however, income taxes on profits which may be levied against Provider.
  12. Warranties.
    1. Customer Warranty. Customer represents and warrants that: (a) it has full power, capacity, and authority to enter into this Agreement and to grant the licenses set forth in Section 9 and Section 10; (b) any Customer Data provided by Customer to Provider for use in connection with the Services does not and will not infringe the intellectual property, publicity, or privacy rights of any person and is not defamatory, obscene, or in violation of applicable law (including applicable laws related to spamming, privacy, and consumer protection); and (c) its use of the Services will be in compliance with all applicable law.
    2. Provider Warranty. During the Term, Provider represents and warrants that: (a) the Services will substantially comply with the Documentation; (b) it will use commercially reasonable efforts to screen the Services for viruses, Trojan horses, worms, and other similar intentionally harmful or destructive code; and (c) it will comply with applicable law in performing this Agreement. In the event of a breach of the warranty in Section 12.2(a), Provider’s sole and exclusive liability and Customer’s sole and exclusive remedy will be to perform the defective Service again. In the event Provider is unable through reasonable efforts to correct the defective Service within thirty (30) days from receipt of notice from Customer of the breach, Customer may elect to terminate this Agreement and receive a pro-rated refund of any pre-paid, unused recurring fees for the non-conforming Services.
    3. Disclaimer of Warranties. EXCEPT AS PROVIDED IN SECTION 12.2 (PROVIDER WARRANTY), THE SERVICES ARE PROVIDED “AS IS” AND “AS-AVAILABLE,” WITH ALL FAULTS, AND WITHOUT WARRANTIES OF ANY KIND. PROVIDER AND ITS VENDORS AND LICENSORS DISCLAIM ALL OTHER WARRANTIES, EXPRESS AND IMPLIED, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT, QUALITY OF INFORMATION, AND TITLE/NON-INFRINGEMENT. NO ORAL OR WRITTEN INFORMATION OR ADVICE GIVEN BY PROVIDER OR ITS AUTHORIZED REPRESENTATIVES WILL CREATE ANY OTHER WARRANTIES OR IN ANY WAY INCREASE THE SCOPE OF PROVIDER’S OBLIGATIONS HEREUNDER. THE SERVICES MAY BE USED TO ACCESS AND TRANSFER INFORMATION OVER THE INTERNET. CUSTOMER ACKNOWLEDGES AND AGREES THAT PROVIDER AND ITS VENDORS AND LICENSORS DO NOT OPERATE OR CONTROL THE INTERNET AND THAT (I) VIRUSES, WORMS, TROJAN HORSES, OR OTHER UNDESIRABLE DATA OR SOFTWARE OR (II) UNAUTHORIZED USERS (E.G., HACKERS) MAY ATTEMPT TO OBTAIN ACCESS TO AND DAMAGE CUSTOMER’S DATA, WEBSITES, COMPUTERS, OR NETWORKS. PROVIDER WILL NOT BE RESPONSIBLE FOR SUCH ACTIVITIES. CUSTOMER IS RESPONSIBLE FOR PRESERVING AND MAKING ADEQUATE BACKUPS OF ITS DATA.
  13. Provider Indemnity. Provider will defend and indemnify Customer and hold it harmless from any and all claims, losses, deficiencies, damages, liabilities, costs, and expenses (including reasonable attorneys’ fees) arising from a claim by a third party that Customer’s use of the Services infringes that third party’s Intellectual property rights. The foregoing indemnification obligation of Provider is contingent upon Customer promptly notifying Provider in writing of such claim, permitting Provider sole authority to control the defense or settlement of such claim and providing Provider reasonable assistance (at Provider’s sole expense) in connection therewith. If a claim of infringement under this Section 13 occurs, or if Provider determines a claim is likely to occur, Provider will have the right, in its sole discretion, to either: (a) procure for Customer the right or license to continue to use the Services free of the infringement claim; or (b) modify the Services to make them non-infringing, without loss of material functionality. If neither of these remedies is reasonably available to Provider, Provider may, in its sole discretion, immediately terminate this Agreement and return the prorated portion of any pre-paid, unused fees for the relevant Services. Notwithstanding the foregoing, Provider will have no obligation with respect to any claim of infringement that is based upon or arises out of (i) the use or combination of the Services with any hardware, software, products, data, or other materials not provided by Provider; (ii) modification or alteration of the Services by anyone other than Provider; (iii) use of Services in violation of, or excess of the rights granted in, this Agreement; or (iv) any specifications or other intellectual property provided by Customer, including the Customer Data (collectively, the “Excluded Claims”), all of which are expressly disclaimed.
  14. Customer Indemnity. Customer will defend and indemnify Provider and hold it harmless from any and all claims, losses, deficiencies, damages, liabilities, costs, and expenses (including reasonable attorneys’ fees) incurred by Provider as a result of any claim by a third party arising from the Excluded Claims. The foregoing indemnification obligation of Customer is contingent upon Provider promptly notifying Customer in writing of such claim, permitting Customer sole authority to control the defense or settlement of such claim and providing Customer reasonable assistance (at Customer’s sole expense) in connection therewith.
  15. Confidentiality; Publicity.
    1. Definition of Confidential Information. In connection with this Agreement, each party (as the “Disclosing Party”) may disclose or make available certain Confidential Information to the other party (as the “Receiving Party”). “Confidential Information” means information in any form or medium (whether oral, written, electronic, or other) that the Disclosing Party considers confidential or proprietary, whether or not identified as “confidential”, including information consisting of or relating to the Disclosing Party’s technology, trade secrets, know-how, business operations, plans, strategies, customers, or pricing, and information with respect to which the Disclosing Party has contractual or other confidentiality obligations. Without limiting the foregoing, the Services (including the “look and feel” and user interface thereof) and Documentation are Provider’s Confidential Information, and the Customer Data is Customer’s Confidential Information.
    2. Exclusions. Confidential Information does not include any information or material, that: (a) has previously become or is generally known, through no fault of the Receiving Party; (b) was already rightfully known to the Receiving Party prior to being disclosed by or obtained from the Disclosing Party as evidenced by written records; (c) has been or is hereafter rightfully received by the Receiving Party from a third person without restriction; or (d) has been independently developed by the Receiving Party without access to Confidential Information of the Disclosing Party.
    3. Treatment of Confidential Information. Unless otherwise authorized in the Agreement, the Receiving Party will (a) only use the Disclosing Party’s Confidential Information to fulfill its obligations or exercise its rights under this Agreement (including disclosure to its End Users, employees, advisors, contractors, and representatives who each have a need to know the confidential information, only if such person or entity is bound by confidentiality obligations at least as protective as those in this Section 15); and (b) not disclose the Disclosing Party’s Confidential Information to anyone else. In addition, the Receiving Party will protect the Disclosing Party’s Confidential Information using at least the same protections the Receiving Party uses for its own similar information but no less than a reasonable standard of care.
    4. Compelled Disclosures. The Receiving Party may disclose the Disclosing Party’s Confidential Information to the extent required by applicable law if, unless prohibited by applicable law, the Receiving Party provides the Disclosing Party’s reasonable advance notice of the required disclosure and reasonably cooperates, at the Disclosing Party’s expense, with the Disclosing Party’s efforts to obtain confidential treatment for the Confidential Information.
    5. Return of Confidential Information. On termination or expiration of this Agreement, the Receiving Party will return or destroy, at the Disclosing Party’s option, the Disclosing Party’s Confidential Information. Notwithstanding the foregoing, the Receiving Party will not be required to remove copies of the Disclosing Party’s Confidential Information from its backup media and servers, where doing so would be commercially impracticable. In addition, the foregoing destruction and return obligation will be subject to any retention obligations imposed on Receiving Party by law or regulation.
    6. Non-Exclusive Equitable Remedy. Each party acknowledges and agrees that due to the unique nature of the Confidential Information there can be no adequate remedy at law for any breach of its obligations hereunder, that any such breach or threatened breach may allow a party or third parties to unfairly compete with the other party, resulting in irreparable harm to such party, and therefore, that upon any such breach or any threat thereof, each party will be entitled to appropriate equitable and injunctive relief from a court of competent jurisdiction without the necessity of proving actual loss, in addition to whatever remedies either of them might have at law or equity before an arbitrator in accordance with the arbitration provision of this Agreement. Any breach of this Section 15 will constitute a material breach of this Agreement and be grounds for immediate termination of this Agreement in the exclusive discretion of the non-breaching party. 
    7. Publicity. Notwithstanding the foregoing, with the prior written consent of Customer (which shall not be unreasonably withheld, conditioned, or delayed), Provider may identify Customer as a customer in its customer listings, websites, and other promotional materials.
  16. Limitation of Liability and Damages. NEITHER PROVIDER NOR ITS VENDORS OR LICENSORS WILL HAVE ANY LIABILITY TO CUSTOMER OR ANY THIRD PARTY FOR ANY LOSS OF PROFITS, SALES, TRADING LOSSES, BUSINESS, DATA, OR OTHER INCIDENTAL, CONSEQUENTIAL, OR SPECIAL LOSS OR DAMAGE, INCLUDING EXEMPLARY AND PUNITIVE DAMAGE, OF ANY KIND OR NATURE RESULTING FROM OR ARISING OUT OF THIS AGREEMENT, INCLUDING USE OF OR INABILITY TO USE THE SERVICES. THE TOTAL LIABILITY OF PROVIDER AND ITS VENDORS AND LICENSORS TO CUSTOMER OR ANY THIRD PARTY ARISING OUT OF THIS AGREEMENT OR USE OF THE SERVICES IN CONNECTION WITH ANY CLAIM OR TYPE OF DAMAGE (WHETHER IN CONTRACT OR TORT, INCLUDING NEGLIGENCE) WILL NOT EXCEED THE TOTAL FEES PAID HEREUNDER BY CUSTOMER DURING THE THREE (3) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE LIABILITY. THIS LIMITATION OF LIABILITY WILL APPLY EVEN IF THE EXPRESS WARRANTIES SET FORTH ABOVE FAIL OF THEIR ESSENTIAL PURPOSE. NOTWITHSTANDING THE FOREGOING AND WITHOUT LIMITING THE GENERALITY OF THE DISCLAIMERS AND LIMITATIONS DESCRIBED IN SECTION 2.2, PROVIDER SHALL HAVE NO INDEMNIFICATION OBLIGATIONS NOR LIABILITY OF ANY TYPE WITH RESPECT TO BETA SERVICES, UNLESS SUCH EXCLUSION OF LIABILITY IS NOT ENFORCEABLE UNDER APPLICABLE LAW, IN WHICH CASE PROVIDER’S AGGREGATE LIABILITY FOR ALL DAMAGES OF EVERY KIND AND TYPE WITH RESPECT TO SUCH BETA SERVICES, AS APPLICABLE, WILL NOT EXCEED THE TOTAL FEES PAID HEREUNDER BY CUSTOMER SPECIFICALLY FOR THE BETA SERVICES.
  17. Termination.
    1. Termination. This Agreement will terminate: (a) thirty (30) days after either party gives the other written notice of a breach by the other of any material term or condition of this Agreement, unless the breach is cured before that day; or (b) upon written notice by either party, immediately, if (i) a receiver is appointed for the other party or its property; (ii) the other party becomes insolvent or unable to pay its debts as they mature in the ordinary course of business or makes a general assignment for the benefit of its creditors; or (iii) any proceedings (whether voluntary or involuntary) are commenced against the other party under any bankruptcy or similar law and such proceedings are not vacated or set aside within sixty (60) days from the date of commencement thereof.
    2. Suspension of Services. Notwithstanding any other provision of this Agreement, Provider may, in its sole discretion, suspend Customer’s access to the Services for any of the following reasons: (a) to prevent damages or risk to, or degradation of, the Services; (b) to comply with any law, regulation, court order, or other governmental request; (c) to otherwise protect Provider from potential legal liability; or (d) in the event an invoice remains unpaid for more than forty-five (45) or more days from the invoice date. Provider will use reasonable efforts to provide Customer with notice prior to or promptly following any suspension of the Services. Provider will promptly restore access to the Services as soon as the event giving rise to suspension has been resolved. This Section 17.2 will not be construed as imposing any obligation or duty on Provider to monitor use of the Services.
    3. Effect of Termination. Upon termination of this Agreement or termination of a particular Service for any reason: (a) Customer’s and all End User’s access to and use of the Services will cease as of the effective date of termination; (b) Customer will pay to Provider all undisputed sums due to Provider for Services through the effective date of such expiration or termination (prorated as appropriate); (c) at Provider’s standard time and materials rates, Provider will reasonably cooperate with Customer in transitioning the Customer Data back to Customer and (d) subject to Section 15.5, Provider will delete all Customer Data stored in the Service.
  18. General Provisions. This Agreement, together with all related Schedules and all Order Forms, sets forth the entire agreement between the parties with regard to the subject matter hereof, and supersedes all prior or contemporaneous understandings, or agreements, both written and oral. No amendment to or modification of this Agreement is effective unless it is made in writing and signed by an authorized representative of each party. Except for the payment of fees as described in Section 11 of this Agreement, neither party will be liable for any failure or delay in performance under this Agreement which is due to any event beyond the reasonable control of such party, including fire, explosion, unavailability of utilities or raw materials, Internet delays and failures, telecommunications failures, unavailability of components, labor difficulties, war, riot, act of God, export control regulation, laws, judgments or government instructions. This Agreement will be construed according to, and the rights of the parties will be governed by, the laws of the State of California, without reference to its conflict of laws rules. The parties agree that all actions or proceedings arising in connection with this Agreement will be tried and litigated exclusively in the state or federal courts located in San Francisco County, California. The prevailing party in any action or proceeding will be entitled to recover its reasonable attorneys’ fees and costs. The parties agree that Provider will perform its duties under this Agreement as an independent contractor. Nothing contained in this Agreement will be deemed to establish a partnership, joint venture, association, or employment relationship between the parties. Customer may not assign this Agreement without the prior written consent of Provider. If any of the provisions of this Agreement are found or deemed by a court to be invalid or unenforceable, they will be severable from the remainder of this Agreement and will not cause the invalidity or unenforceability of the remainder of this Agreement. The following provisions will survive termination or expiration of this Agreement: 8 (Proprietary Rights), 12.3 (Disclaimer of Warranties), 13 (Provider Indemnity) (for claims accruing prior to termination), 14 (Customer Indemnity) (for claims accruing prior to termination), 15 (Confidentiality), 16 (Limitation of Liability and Damages), 17 (Termination), and 18 (General Provisions). All notices under this Agreement will be in writing and will be deemed to have been duly given when received, if personally delivered; when receipt is electronically confirmed, if transmitted by facsimile or e-mail; the day after it is sent, if sent for next day delivery by recognized overnight delivery service; and upon receipt, if sent by certified or registered mail, return receipt requested. 
Excused Outages

Schedule A

Service Level Terms

These Service Level Terms (“Service Level Terms”) form part of the Services Agreement between Roadway AI, Inc. (“Provider”) and Customer (the “Agreement”) under which Provider provides the Services to Customer. Capitalized terms used but not defined herein shall have the meaning as set forth in the Agreement.

  1. Availability. For purposes of this Schedule A, the Services mean the Provider SaaS Services. The hosted elements of the Services will be available for remote access 99.9% of the time each calendar month of the Term, excluding Excused Outages (“Availability”). Downtime as a result of any causes beyond the reasonable control of Provider or that are not reasonably foreseeable by Provider, including by any of the events noted below, are excluded from the Availability calculations (collectively, “Excused Outages”):
    1. Customer Systems or other Customer environment issues affecting connectivity or interfering with the Services, including Customer’s telecommunications connection or any other Customer System, Customer’s firewall software, hardware, or security settings, Customer’s configuration of anti-virus software or anti-spyware or malware software, or operator error of Customer;
    2. any third-party software, hardware, or telecommunication failures, including Internet slow-downs or failures;
    3. force majeure events, including fire, flood, earthquake, elements of nature or acts of God; third-party labor disruptions, acts of war, terrorism, riots, civil disorders, rebellions or revolutions; quarantines, embargoes and other similar governmental action; or any other similar cause beyond the reasonable control of Provider;
    4. issues related to third-party domain name system (DNS) errors or failures;
    5. scheduled maintenance of the Services, conducted either (i) on a regular basis between 6:00 PM and 6:00 AM Pacific Time; or (ii) at other times outside such regularly scheduled windows in which case Provider will give Customer a minimum of twenty-four (24) hours advanced notice by email or other pre-approved notification; and
    6. emergency maintenance of the Services, not to exceed four (4) hours in any month, for which Customer may not receive advanced notice.
  1. Data Limits. The Services have a maximum data usage limit, which is set forth in the Order Form or, solely to the extent not inconsistent with the Order Form, as set forth in the Documentation. Customer must not use the Services in a manner that exceeds the maximum data usage limit. Customer will be responsible for charges for any data usage above the data usage limit, as set out in the Order Form, paid in arrears.
  1. Support and Maintenance. During the Term, Provider will provide Customer with reasonable technical support in the manner that Provider generally provides its customers during Provider’s business hours, and Provider will use commercially reasonable efforts to correct reproducible failures of the Services to perform in substantial accordance with their then current Documentation. Provider will make available to Customer the Services updates and bug fixes that Provider in its sole discretion makes generally available to its other similarly situated customers at no charge. However, Customer shall not be entitled to receive updates or new releases that include new or different functionality for which Provider imposes an additional charge to its customers. Such new or different functionality may be purchased by Customer, in its discretion, at Provider’s then current pricing.

Schedule B 

Data Processing Addendum

This Data Protection Addendum (“DPA”) forms part of the Services Agreement between Roadway AI, Inc. (“Provider”) and Customer (the “Agreement”) under which Provider provides the Services to Customer. Capitalized terms used but not defined in this DPA shall have the meaning as set forth in the Agreement.

  1. Definitions
    1. Controller” means the entity which, alone or jointly with others, determines the purposes and means of Processing of Personal Data.
    2. Customer Personal Data” means Personal Data that is provided by the Customer to the Services and is not Services Data.
    3. Data Protection Laws” mean all laws applicable to the respective Party’s Processing of Personal Data.
    4. Data Subject” means any individual about whom Personal Data may be Processed under this DPA.
    5. Personal Data” means information that relates to an identified or identifiable natural person.
    6. Process” or “Processing” means any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaption or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction of Personal Data.
    7. Processor” means the entity which Processes Personal Data on behalf of the Data Controller.
    8. Services Data” means data that relates to Provider’s relationship with Customer, including (i) contact information of individuals authorized by Customer to access Customer’s account; (ii) any data Provider may need to collect for the purpose of managing its relationship with Customer, identity verification, or as otherwise required by applicable laws and regulations; (iii) Service use data collected in connection with the provision of the Services, including data used to identify the source and destination of a communication, activity logs, and data used to optimize and maintain performance of the Services, and to investigate and prevent system abuse.
  2. Relationship between the Parties. Customer and Provider have entered into an Agreement for Services. The Parties acknowledge that for purposes of any Customer Personal Data processed pursuant to the Agreement, Customer is a Controller or Processor and Provider is a Processor. The Parties will Process Customer Personal Data in accordance with the Agreement and applicable Data Protection Laws.
  3. Customer Obligations. Customer will provide only the Customer Personal Data that is adequate, relevant, and reasonably necessary for Provider to perform the Services. Such Customer Personal Data will be limited to the personal data described by customer in the applicable Order Form. Customer represents and warrants that its collection of Customer Personal Data and disclosure to Provider complies with all applicable Data Protection Laws.
  4. Instructions. Provider will Process the Customer Personal Data only (i) in accordance with the Customer’s instructions as documented in the Agreement or any Order Form; and (ii) as needed to comply with applicable law, provided that Provider shall not be required to act on any Customer instruction that could (in Provider’s reasonable opinion) cause Provider to breach applicable law. Provider will inform Customer if it believes that any Customer instructions regarding Customer Personal Data Processing would violate applicable Data Protection Law.
  5. Security. Provider will take reasonable steps to implement appropriate technical and organizational measures designed to protect Customer Personal Data against anticipated threats or hazards to its security, confidentiality, or integrity. Provider will ensure that persons authorized to Process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Annex I sets forth additional information regarding Provider’s technical and organizational security measures.
  6. Data Breach. Provider will notify Customer without undue delay (and in any case within 72 hours) whenever Provider learns that there has been a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data Processed (each, a “Data Breach”), unless prohibited by applicable law or otherwise instructed by law enforcement or a supervisory authority. Taking into account the nature of Processing and the information available to Provider, Provider will take reasonable steps to assist the Customer at Customer’s reasonable request in complying with the Customer’s notification obligations regarding data breaches as required by applicable law. 
  7. Return or Disposal. Following completion of the Services, Provider will destroy or return all Customer Personal Data to Customer, unless applicable law requires or authorizes storage of the Customer Personal Data by Provider.
  8. Audits; Inquiries. Upon Customer’s reasonable request (exercisable no more than once a year, unless required more frequently by a supervisory authority) Provider will make available for Customer’s review copies of certifications or reports demonstrating Provider’s compliance with its obligations under this DPA. If the provision of reports or certifications is not reasonably sufficient under Data Protection Laws, Provider will allow an independent third party to be mutually agreed on by the parties to conduct an audit or inspection of Provider’s data security infrastructure and procedures that is sufficient to demonstrate Provider’s compliance with its obligations under this DPA, provided that (i) Customer provides sixty (60) days’ prior written notice of any such request for an audit and such inspection shall not be unreasonably disruptive to Provider’s business; (ii) such audit shall only be performed during business hours and occur no more than once per calendar year; and (iii) such audit shall be restricted to data relevant to Customer. Customer shall be responsible for the costs of any such audits or inspections, including reimbursing Provider for any time expended for on-site audits. All information provided will be Provider’s Confidential Information and may not be disclosed without Provider’s prior written consent, except as required by applicable law.
  9. Subcontracting. Customer authorizes Provider to transfer Customer Personal Data to sub-processors for purposes of providing the Services to Customer. Provider will maintain a list of the sub-processors and will provide this list to Customer upon request. Provider will provide Customer fourteen (14) days’ prior notice when adding a sub-processor to this list and the opportunity to object to such addition. If Provider does not receive an objection within fourteen (14) days of the notice, the sub-processor is deemed to be accepted by Customer. Provider will enter into an agreement with such sub-processor that includes data protection terms similar to this DPA.
  10. Provider Assistance. At Customer’s reasonable request and taking into account the nature of the Processing and information available to Provider, Provider will take reasonable steps: (i) to assist Customer with Customer’s obligation to respond to Data Subjects’ requests to exercise their rights under applicable law by taking appropriate technical and organizational measures; and (ii) in meeting Customer’s compliance obligations to carry out data protection impact assessments and related consultations with supervisory authorities. 
  11. California Consumer Privacy Act (CCPA) Provisions.
    1. Legal Compliance. Provider will provide the same level of privacy protection for Customer Personal Data of California residents as required of Customer under the CCPA. Provider will notify Customer in writing if Provider determines that it can no longer meet its obligations under the CCPA. Customer has the right, upon providing notice to Provider, to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data, including where Provider has notified Customer that it can no longer meet its CCPA obligations.
    2. Restriction on Processing. In no event may Provider: (a) disclose Customer Personal Data of California residents to a third party for monetary or other valuable consideration or disclose Customer Personal Data to a third party for cross-context behavioral advertising; (b) disclose Customer Personal Data of California residents to any third party for the commercial benefit of Provider or any third party; (c) retain, use, or disclose Customer Personal Data of California residents outside of Provider’s direct business relationship with Customer or for a commercial purpose other than the business purposes specified in the Agreement or as otherwise permitted by applicable laws; or (d) combine Customer Personal Data of California residents with personal information that Provider receives from, or on behalf of, other persons, or collects from its own interaction with the Data Subject, except as permitted under applicable laws. Provider certifies that it understands and will comply with the foregoing restrictions.
  12. Data Transfers.
    1. Customer acknowledges that Provider’s primary processing operations take place in the United States and the processing of Customer Personal Data in the United States is necessary for Provider to provide the Services to Customer. The parties agree that Provider also may transfer Customer Personal Data processed under this DPA outside the United States as necessary to provide the Services.
    2. Restricted Transfers from the EEA. The EU Standard Contractual Clauses (Module 2 Controller to Processor) ((EU)2021/914) available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?uri=CELEX%3A32021D0914&locale=en (“EU SCCs”), and incorporated herein by reference, together with the attached Annex I will apply as completed below to any transfer to Provider of Customer Personal Data from Customer in the European Economic Area (EEA). Notwithstanding the foregoing, the EU SCCs will not apply to the extent the transfer is covered by a decision adopted by a competent authority with jurisdiction over Customer declaring that a jurisdiction meets an adequate level of protection of Customer Personal Data (an “Adequacy Decision”). Signature to the Agreement will be considered a signature to the EU SCCs. The parties agree that the EU SCCs will be completed as follows:
      1. Optional Clause 7 is removed.
      2. In Clause 9, the parties agree that Option 2 will apply in accordance with Section 9 (Subcontracting) of this DPA.
      3. The optional language in Clause 11 is excluded.
      4. In Clause 17, the EU SCCs will be governed by the laws of Ireland.
      5. In Clause 18, any dispute arising from the EU SCCs will be resolved by the courts of Ireland.
      6. In Annex IC, the data protection authority where Customer is located is the competent supervisory authority.
    3. Restricted Transfers from Switzerland. The EU SCCs, as modified in this section, will apply to any transfer to Provider of Customer Personal Data from Customer in Switzerland where the transfer is not otherwise subject to an Adequacy Decision:
      1. The term “EU Member State” must not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility for suing their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c).
      2. References in the EU SCCs to the GDPR are to be understood as references to the FADP.
      3. In Clause 17, the EU SCCs will be governed by the laws of Switzerland.
      4. In Annex IC, the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority.
    4. Restricted Transfers from the United Kingdom. Where Customer Personal Data is transferred to Provider from

Customer in the UK and the transfer is not otherwise subject to an Adequacy Decision, the parties agree:

  1. The provisions of the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, Version B1.0, in force from March 21, 2022, available at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf (“UK Addendum”) are herein incorporated by reference and shall apply in full;
  2. In Table 1 of the UK Addendum, the names of the parties, their roles and their details shall be set out in the attached Annex 1;
  3. In Tables 2 and 3 of the UK Addendum, Module 2 of the EU SCCs incorporated into this DPA by reference, including the information set out in the attached Annex, shall apply; and
  4. In Table 4 of the UK Addendum, either party may end the UK Addendum.
  1. Services Data. The parties acknowledge and agree that Provider is an independent controller with respect to Services Data. Provider will process Services Data in accordance with the Provider’s privacy policy set forth at https://www.roadwayai.com/privacy-policy.
  2. Conflicts; Enforceability. If any provision of this DPA is held to be invalid or unenforceable by any court of competent jurisdiction, such holding will not invalidate or render unenforceable any other provision of this DPA or any other contract between Customer and Provider. This DPA supplements the Agreement. This DPA will control in the event of any inconsistency between the Agreement and this DPA. Any other provisions of or obligations under the Agreement that are otherwise unaffected by this DPA will remain in full force and effect. If this DPA, or any actions to be taken or contemplated to be taken in performance of this DPA, do not or would not satisfy either party’s obligations under the laws applicable to each party, the parties will negotiate in good faith upon an appropriate amendment to this DPA.

ANNEX I

SECURITY MEASURES

This appendix represents the security measures that will be taken by Provider.

  1. Information Security Policies and Standards. Provider will implement security requirements for personnel with access to Customer Personal Data that are designed to ensure a level of security appropriate to the risk and address the requirements as detailed in this Annex. Provider will conduct periodic risk assessments and, as appropriate, revise its information security practices whenever there is a material change in Provider’s business practices that may reasonably affect the security, confidentiality, or integrity of Customer Personal Data, provided that Provider will not modify its information security practices in a manner that will materially weaken Customer Personal Data protection.
  2. Physical Security. Provider will maintain commercially reasonable security systems at all Provider sites where an information system that uses or houses Customer Personal Data is located. Provider reasonably restricts access to such Customer Personal Data appropriately and has in place practices to prevent unauthorized individuals from gaining access to Customer Personal Data.
  3. Organizational Security.
  • Upon Controller’s request, Provider will provide contact information for its designated primary security manager.
  • Provider will implement procedures to prevent any subsequent retrieval of any Customer Personal Data stored on media before disposed of or reused.
  • Provider will implement security policies and procedures to classify sensitive information assets, clarify security responsibilities and promote awareness for employees.
  • Provider will manage all Customer Personal Data breaches in accordance with appropriate procedures.
  • Provider will encrypt, using industry-standard encryption tools, Customer Personal Data that Provider: (i) transmits or sends wirelessly or across public networks; and (ii) stores on portable devices or at rest, where technically feasible.
  1. Network Security. Provider maintains network security using commercially available equipment and industry-standard techniques, including firewalls, intrusion detection and prevention systems, access control lists and routing protocols.
  2. Access Control. Provider will maintain appropriate access controls, including restricting access to Customer Personal Data to the minimum number of Provider personnel who require such access.
  3. Virus and Malware Controls. Provider will install and maintain anti-virus and malware protection software on the system and has in place scheduled malware monitoring and system scanning to protect Customer Personal Data from anticipated threats or hazards and against unauthorized access or use.
  4. Personnel. Provider will require personnel to comply with its Information Security Program. Provider will train personnel about their security obligations.
  5. Business Continuity. Provider will implement appropriate back-up and disaster recovery and business resumption plans. Provider will regularly review, test, and update its business continuity plan.